Denial of Service Vulnerability in WildFly Core by Red Hat
CVE-2026-24329
4.9MEDIUM
What is CVE-2026-24329?
A flaw in WildFly Core allows authenticated remote users with administrative privileges to inject a malformed payload into the Inet Address field through the Management Model. This action leads to server crashes and render the system unrecoverable, as the corrupted payload is written into the standalone.xml configuration file. Recovery requires manual intervention, causing denial of service for affected systems.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Claudia Bartolini (TIM Security Red Team Research - TIM S.p.A), Marco Ventura (TIM Security Red Team Research - TIM S.p.A), and Massimiliano Brolli (TIM Security Red Team Research - TIM S.p.A) for reporting this issue.